Improper Authentication in vCenter Server - CVE-2021-22012
Published: September 21, 2021
Vulnerability identifier: #VU56801
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22012
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication to the appliance management API. A remote non-authenticated attacker can with access to port 443/TCP can gain access to sensitive information on the system.
Affected software
vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Dell EMC VxRail Appliance
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22012
Install updates from vendor's website.
vCenter Server - update to 6.5 U3q
EMC Integrated Data Protection Appliance - update to 2.7.0
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
EMC Integrated Data Protection Appliance - update to 2.7.0
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241